From 8085ca176b08d76c98ccb75084fd336df61af3b3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?K=C3=A9vin=20Chalet?= Date: Fri, 31 Jul 2020 14:33:52 +0200 Subject: [PATCH] Translate all the error messages into French and remove the duplicate .resx entries --- Directory.Build.props | 2 +- samples/Mvc.Server/Startup.cs | 7 + .../OpenIddict.Abstractions.csproj | 4 +- .../Resources/OpenIddictResources.resx | 513 ++++++++++++++- .../Resources/xlf/OpenIddictResources.fr.xlf | 592 ++++++++++++++++++ .../OpenIddictServerDataProtectionHandlers.cs | 2 +- ...OpenIddictServerHandlers.Authentication.cs | 2 +- .../OpenIddictServerHandlers.Exchange.cs | 8 +- .../OpenIddictServerHandlers.Introspection.cs | 4 +- .../OpenIddictServerHandlers.Revocation.cs | 4 +- .../OpenIddictServerHandlers.cs | 2 +- ...nIddictValidationDataProtectionHandlers.cs | 2 +- .../OpenIddictValidationHandlers.cs | 8 +- ...ctServerIntegrationTests.Authentication.cs | 2 +- ...nIddictServerIntegrationTests.Discovery.cs | 2 +- ...enIddictServerIntegrationTests.Exchange.cs | 8 +- ...ictServerIntegrationTests.Introspection.cs | 4 +- ...IddictServerIntegrationTests.Revocation.cs | 4 +- 18 files changed, 1113 insertions(+), 57 deletions(-) create mode 100644 src/OpenIddict.Abstractions/Resources/xlf/OpenIddictResources.fr.xlf diff --git a/Directory.Build.props b/Directory.Build.props index 6de0e556..4ca83468 100644 --- a/Directory.Build.props +++ b/Directory.Build.props @@ -9,7 +9,7 @@ true $(MSBuildThisFileDirectory)eng\CodeAnalysis.ruleset true - false + fr diff --git a/samples/Mvc.Server/Startup.cs b/samples/Mvc.Server/Startup.cs index 9050302e..7051d4f3 100644 --- a/samples/Mvc.Server/Startup.cs +++ b/samples/Mvc.Server/Startup.cs @@ -161,6 +161,13 @@ namespace Mvc.Server app.UseRouting(); + app.UseRequestLocalization(options => + { + options.AddSupportedCultures("en-US", "fr-FR"); + options.AddSupportedUICultures("en-US", "fr-FR"); + options.SetDefaultCulture("en-US"); + }); + app.UseAuthentication(); app.UseAuthorization(); diff --git a/src/OpenIddict.Abstractions/OpenIddict.Abstractions.csproj b/src/OpenIddict.Abstractions/OpenIddict.Abstractions.csproj index 97eabd87..31dc6a68 100644 --- a/src/OpenIddict.Abstractions/OpenIddict.Abstractions.csproj +++ b/src/OpenIddict.Abstractions/OpenIddict.Abstractions.csproj @@ -32,8 +32,8 @@ - - + diff --git a/src/OpenIddict.Abstractions/Resources/OpenIddictResources.resx b/src/OpenIddict.Abstractions/Resources/OpenIddictResources.resx index f53a180c..c1ec16fa 100644 --- a/src/OpenIddict.Abstractions/Resources/OpenIddictResources.resx +++ b/src/OpenIddict.Abstractions/Resources/OpenIddictResources.resx @@ -120,969 +120,1244 @@ An identity cannot be extracted from this token request. This generally indicates that the OpenIddict server stack was asked to validate a token for an invalid grant type (e.g password). + {Locked} An identity cannot be extracted from this request. This generally indicates that the OpenIddict server stack was asked to validate a token for an endpoint it doesn't manage. To validate tokens received by custom API endpoints, the OpenIddict validation services must be used instead. + {Locked} The token type is not supported. + {Locked} The deserialized principal doesn't contain the mandatory 'oi_tkn_typ' claim. When implementing custom token deserialization, a 'oi_tkn_typ' claim containing the type of the token being processed must be added to the security principal. + {Locked} The type of token associated with the deserialized principal ({0}) doesn't match the expected token type ({1}). + {Locked} A challenge response cannot be returned from this endpoint. + {Locked} The authentication context cannot be found. + {Locked} The device code identifier cannot be extracted from the principal. + {Locked} The token identifier cannot be extracted from the principal. + {Locked} A sign-in response cannot be returned from this endpoint. + {Locked} The specified principal doesn't contain any claims-based identity. Make sure that 'ClaimsPrincipal.Identity' is not null. + {Locked} The specified principal contains an authenticated identity, which is not valid when the sign-in operation is triggered from the device authorization endpoint. Make sure that 'ClaimsPrincipal.Identity.AuthenticationType' is null and that 'ClaimsPrincipal.Identity.IsAuthenticated' returns 'false'. + {Locked} The specified principal contains a subject claim, which is not valid when the sign-in operation is triggered from the device authorization endpoint. + {Locked} The specified principal doesn't contain a valid/authenticated identity. Make sure that 'ClaimsPrincipal.Identity.AuthenticationType' is not null and that 'ClaimsPrincipal.Identity.IsAuthenticated' returns 'true'. + {Locked} The specified principal was rejected because the mandatory subject claim was missing. + {Locked} The core services must be registered when enabling the OpenIddict server feature. To register the OpenIddict core services, reference the 'OpenIddict.Core' package and call 'services.AddOpenIddict().AddCore()' from 'ConfigureServices'. Alternatively, you can disable the built-in database-based server features by enabling the degraded mode with 'services.AddOpenIddict().AddServer().EnableDegradedMode()'. + {Locked} The application entry cannot be found in the database. + {Locked} An unknown error occurred while creating an authorization entry. + {Locked} An unknown error occurred while creating a token entry. + {Locked} A token entry cannot be created from a null principal. + {Locked} The token entry cannot be found in the database. + {Locked} A token cannot be created from a null principal. + {Locked} The issuer must be a non-null, non-empty absolute URL. + {Locked} A sign-out response cannot be returned from this endpoint. + {Locked} The token type cannot be resolved. + {Locked} The payload associated with a reference token cannot be retrieved. This may indicate that the token entry was corrupted. + {Locked} The authorization request was not correctly extracted. To extract authorization requests, create a class implementing 'IOpenIddictServerHandler<ExtractAuthorizationRequestContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The request cannot be validated because no redirect_uri was specified. + {Locked} The authorization request was not handled. To handle authorization requests in a controller, create a custom action with the same route as the authorization endpoint and enable the pass-through mode in the server ASP.NET Core or OWIN options using 'services.AddOpenIddict().AddServer().UseAspNetCore().EnableAuthorizationEndpointPassthrough()'. Alternatively, create a class implementing 'IOpenIddictServerHandler<HandleAuthorizationRequestContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The authorization response was not correctly applied. To apply authorization responses, create a class implementing 'IOpenIddictServerHandler<ApplyAuthorizationResponseContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The device request was not correctly extracted. To extract device requests, create a class implementing 'IOpenIddictServerHandler<ExtractDeviceRequestContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The client application details cannot be found in the database. + {Locked} The device response was not correctly applied. To apply device responses, create a class implementing 'IOpenIddictServerHandler<ApplyDeviceResponseContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The verification request was not correctly extracted. To extract verification requests, create a class implementing 'IOpenIddictServerHandler<ExtractVerificationRequestContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The verification request was not handled. To handle verification requests in a controller, create a custom action with the same route as the verification endpoint and enable the pass-through mode in the server ASP.NET Core or OWIN options using 'services.AddOpenIddict().AddServer().UseAspNetCore().EnableVerificationEndpointPassthrough()'. Alternatively, create a class implementing 'IOpenIddictServerHandler<HandleVerificationRequestContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The verification response was not correctly applied. To apply verification responses, create a class implementing 'IOpenIddictServerHandler<ApplyVerificationResponseContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The configuration request was not correctly extracted. To extract configuration requests, create a class implementing 'IOpenIddictServerHandler<ExtractConfigurationRequestContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The cryptography request was not correctly extracted. To extract configuration requests, create a class implementing 'IOpenIddictServerHandler<ExtractCryptographyRequestContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The cryptography response was not correctly applied. To apply cryptography responses, create a class implementing 'IOpenIddictServerHandler<ApplyCryptographyResponseContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The token request was not correctly extracted. To extract token requests, create a class implementing 'IOpenIddictServerHandler<ExtractTokenRequestContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The token request was not handled. To handle token requests in a controller, create a custom action with the same route as the token endpoint and enable the pass-through mode in the server ASP.NET Core or OWIN options using 'services.AddOpenIddict().AddServer().UseAspNetCore().EnableTokenEndpointPassthrough()'. Alternatively, create a class implementing 'IOpenIddictServerHandler<HandleTokenRequestContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The token response was not correctly applied. To apply token responses, create a class implementing 'IOpenIddictServerHandler<ApplyTokenResponseContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The presenters list cannot be extracted from the authorization code. + {Locked} The presenters list cannot be extracted from the device code. + {Locked} The specified code challenge method is not supported. + {Locked} The introspection request was not correctly extracted. To extract introspection requests, create a class implementing 'IOpenIddictServerHandler<ExtractIntrospectionRequestContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The introspection response was not correctly applied. To apply introspection responses, create a class implementing 'IOpenIddictServerHandler<ApplyIntrospectionResponseContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The revocation request was not correctly extracted. To extract revocation requests, create a class implementing 'IOpenIddictServerHandler<ExtractRevocationRequestContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The revocation response was not correctly applied. To apply revocation responses, create a class implementing 'IOpenIddictServerHandler<ApplyRevocationResponseContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The logout request was not correctly extracted. To extract logout requests, create a class implementing 'IOpenIddictServerHandler<ExtractLogoutRequestContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The logout request was not handled. To handle logout requests in a controller, create a custom controller action with the same route as the logout endpoint and enable the pass-through mode in the server ASP.NET Core or OWIN options using 'services.AddOpenIddict().AddServer().UseAspNetCore().EnableLogoutEndpointPassthrough()'. Alternatively, create a class implementing 'IOpenIddictServerHandler<HandleLogoutRequestContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The logout response was not correctly applied. To apply logout responses, create a class implementing 'IOpenIddictServerHandler<ApplyLogoutResponseContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The userinfo request was not correctly extracted. To extract userinfo requests, create a class implementing 'IOpenIddictServerHandler<ExtractUserinfoRequestContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The userinfo response was not correctly applied. To apply userinfo responses, create a class implementing 'IOpenIddictServerHandler<ApplyUserinfoResponseContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The asymmetric encryption key doesn't contain the required private key. + {Locked} An encryption algorithm cannot be automatically inferred from the encrypting key. Consider using 'options.AddEncryptionCredentials(EncryptingCredentials)' instead. + {Locked} The algorithm cannot be null or empty. + {Locked} The specified algorithm is not supported. + {Locked} RSA key generation failed. + {Locked} The specified certificate is not a key encryption certificate. + {Locked} The specified certificate doesn't contain the required private key. + {Locked} The resource cannot be null or empty. + {Locked} The password cannot be null or empty. + {Locked} The certificate was not found in the specified assembly. + {Locked} The thumbprint cannot be null or empty. + {Locked} The certificate corresponding to the specified thumbprint was not found. + {Locked} The asymmetric signing key doesn't contain the required private key. + {Locked} A signature algorithm cannot be automatically inferred from the signing key. Consider using 'options.AddSigningCredentials(SigningCredentials)' instead. + {Locked} ECDSA signing keys are not supported on this platform. + {Locked} The specified certificate is not a signing certificate. + {Locked} The grant type cannot be null or empty. + {Locked} One of the specified addresses is not valid. + {Locked} Claims cannot be null or empty. + {Locked} Scopes cannot be null or empty. + {Locked} The security token handler cannot be null. + {Locked} At least one OAuth 2.0/OpenID Connect flow must be enabled. + {Locked} The authorization endpoint must be enabled to use the authorization code and implicit flows. + {Locked} The device endpoint must be enabled to use the device flow. + {Locked} The token endpoint must be enabled to use the authorization code, client credentials, device, password and refresh token flows. + {Locked} The verification endpoint must be enabled to use the device flow. + {Locked} Reference tokens cannot be used when disabling token storage. + {Locked} Sliding expiration must be disabled when turning off token storage if rolling tokens are not used. + {Locked} At least one encryption key must be registered in the OpenIddict server options. Consider registering a certificate using 'services.AddOpenIddict().AddServer().AddEncryptionCertificate()' or 'services.AddOpenIddict().AddServer().AddDevelopmentEncryptionCertificate()' or call 'services.AddOpenIddict().AddServer().AddEphemeralEncryptionKey()' to use an ephemeral key. + {Locked} At least one asymmetric signing key must be registered in the OpenIddict server options. Consider registering a certificate using 'services.AddOpenIddict().AddServer().AddSigningCertificate()' or 'services.AddOpenIddict().AddServer().AddDevelopmentSigningCertificate()' or call 'services.AddOpenIddict().AddServer().AddEphemeralSigningKey()' to use an ephemeral key. + {Locked} When using X.509 encryption credentials, at least one of the registered certificates must be valid. To use key rollover, register both the new certificate and the old one in the credentials collection. + {Locked} When using X.509 signing credentials, at least one of the registered certificates must be valid. To use key rollover, register both the new certificate and the old one in the credentials collection. + {Locked} No custom authorization request validation handler was found. When enabling the degraded mode, a custom 'IOpenIddictServerHandler<ValidateAuthorizationRequestContext>' must be implemented to validate authorization requests (e.g to ensure the client_id and redirect_uri are valid). + {Locked} No custom device request validation handler was found. When enabling the degraded mode, a custom 'IOpenIddictServerHandler<ValidateDeviceRequestContext>' must be implemented to validate device requests (e.g to ensure the client_id and client_secret are valid). + {Locked} No custom introspection request validation handler was found. When enabling the degraded mode, a custom 'IOpenIddictServerHandler<ValidateIntrospectionRequestContext>' must be implemented to validate introspection requests (e.g to ensure the client_id and client_secret are valid). + {Locked} No custom logout request validation handler was found. When enabling the degraded mode, a custom 'IOpenIddictServerHandler<ValidateLogoutRequestContext>' must be implemented to validate logout requests (e.g to ensure the post_logout_redirect_uri is valid). + {Locked} No custom revocation request validation handler was found. When enabling the degraded mode, a custom 'IOpenIddictServerHandler<ValidateRevocationRequestContext>' must be implemented to validate revocation requests (e.g to ensure the client_id and client_secret are valid). + {Locked} No custom token request validation handler was found. When enabling the degraded mode, a custom 'IOpenIddictServerHandler<ValidateTokenRequestContext>' must be implemented to validate token requests (e.g to ensure the client_id and client_secret are valid). + {Locked} No custom verification request validation handler was found. When enabling the degraded mode, a custom 'IOpenIddictServerHandler<ValidateVerificationRequestContext>' must be implemented to validate verification requests (e.g to ensure the user_code is valid). + {Locked} No custom verification authentication handler was found. When enabling the degraded mode, a custom 'IOpenIddictServerHandler<ProcessAuthenticationContext>' must be implemented to validate device and user codes (e.g by retrieving them from a database). + {Locked} No custom verification sign-in handler was found. When enabling the degraded mode, a custom 'IOpenIddictServerHandler<ProcessSignInContext>' must be implemented to generate device and user codes and storing them in a database, if applicable. + {Locked} The event handler of type '{0}' couldn't be resolved. This may indicate that it was not properly registered in the dependency injection container. To register an event handler, use 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} The event handler filter of type '{0}' couldn't be resolved. This may indicate that it was not properly registered in the dependency injection container. + {Locked} The redirect_uri cannot be null or empty. + {Locked} The authorization request cannot be validated because a different redirect_uri was specified by the client application. + {Locked} The post_logout_redirect_uri cannot be null or empty. + {Locked} The end session request cannot be validated because a different post_logout_redirect_uri was specified by the client application. + {Locked} The specified service type is not valid. + {Locked} No service descriptor was set. + {Locked} The property name cannot be null or empty. + {Locked} The realm cannot be null or empty. + {Locked} The OpenIddict ASP.NET Core server handler cannot be registered as an authentication scheme. This may indicate that an instance of another handler was registered with the same scheme. + {Locked} The OpenIddict ASP.NET Core server cannot be used as the default scheme handler. Make sure that neither DefaultAuthenticateScheme, DefaultChallengeScheme, DefaultForbidScheme, DefaultSignInScheme, DefaultSignOutScheme nor DefaultScheme point to an instance of the OpenIddict ASP.NET Core server handler. + {Locked} The error pass-through mode cannot be used when the status code pages integration is enabled. + {Locked} The OpenID Connect response was not correctly processed. This may indicate that the event handler responsible of processing OpenID Connect responses was not registered or was explicitly removed from the handlers list. + {Locked} An unknown error occurred while retrieving the OpenIddict server context. + {Locked} An error occurred while authenticating the current request. + {Locked} The ASP.NET Core HTTP request cannot be resolved. + {Locked} Only strings, booleans, integers, arrays of strings and instances of type 'OpenIddictParameter' or 'JsonElement' can be returned as custom parameters. + {Locked} A distributed cache instance must be registered when enabling request caching. To register the default in-memory distributed cache implementation, reference the 'Microsoft.Extensions.Caching.Memory' package and call 'services.AddDistributedMemoryCache()' from 'ConfigureServices'. + {Locked} The authorization request payload is malformed. + {Locked} The logout request payload is malformed. + {Locked} The OpenIddict OWIN server handler cannot be used as an active authentication handler. Make sure that 'OpenIddictServerOwinOptions.AuthenticationMode' is not set to 'Active'. + {Locked} The OWIN request cannot be resolved. + {Locked} No service provider was found in the OWIN context. For the OpenIddict server services to work correctly, a per-request 'IServiceProvider' must be attached to the OWIN environment with the dictionary key 'System.IServiceProvider'. Note: when using a dependency injection container supporting middleware resolution (like Autofac), the 'app.UseOpenIddictServer()' extension MUST NOT be called. + {Locked} The OpenIddict server services cannot be resolved from the DI container. To register the server services, use 'services.AddOpenIddict().AddServer()'. + {Locked} Audiences cannot be null or empty. + {Locked} The client identifier cannot be null or empty. + {Locked} The client secret cannot be null or empty. + {Locked} The issuer cannot be null or empty. + {Locked} The issuer must be a valid absolute URL. + {Locked} An OAuth 2.0/OpenID Connect server configuration or an issuer address must be registered. To use a local OpenIddict server, reference the 'OpenIddict.Validation.ServerIntegration' package and call 'services.AddOpenIddict().AddValidation().UseLocalServer()' to import the server settings. To use a remote server, reference the 'OpenIddict.Validation.SystemNetHttp' package and call 'services.AddOpenIddict().AddValidation().UseSystemNetHttp()' and 'services.AddOpenIddict().AddValidation().SetIssuer()' to use server discovery. Alternatively, you can register a static server configuration by calling 'services.AddOpenIddict().AddValidation().SetConfiguration()'. + {Locked} An introspection client must be registered when using introspection. Reference the 'OpenIddict.Validation.SystemNetHttp' package and call 'services.AddOpenIddict().AddValidation().UseSystemNetHttp()' to register the default System.Net.Http-based integration. + {Locked} The issuer or the metadata address must be set when using introspection. + {Locked} The client identifier cannot be null or empty when using introspection. + {Locked} The client secret cannot be null or empty when using introspection. + {Locked} Authorization validation cannot be enabled when using introspection. + {Locked} Token validation cannot be enabled when using introspection. + {Locked} A discovery client must be registered when using server discovery. Reference the 'OpenIddict.Validation.SystemNetHttp' package and call 'services.AddOpenIddict().AddValidation().UseSystemNetHttp()' to register the default System.Net.Http-based integration. + {Locked} The authority must be provided and must be an absolute URL. + {Locked} The authority cannot contain a fragment or a query string. + {Locked} The event handler of type '{0}' couldn't be resolved. This may indicate that it was not properly registered in the dependency injection container. To register an event handler, use 'services.AddOpenIddict().AddValidation().AddEventHandler()'. + {Locked} The core services must be registered when enabling token entry validation. To register the OpenIddict core services, reference the 'OpenIddict.Core' package and call 'services.AddOpenIddict().AddCore()' from 'ConfigureServices'. + {Locked} An unknown error occurred while retrieving the server configuration. + {Locked} An unknown error occurred while introspecting the access token. + {Locked} The core services must be registered when enabling authorization entry validation. To register the OpenIddict core services, reference the 'OpenIddict.Core' package and call 'services.AddOpenIddict().AddCore()' from 'ConfigureServices'. + {Locked} The address cannot be null or empty. + {Locked} The address must be a valid absolute URI. + {Locked} The server configuration couldn't be retrieved. + {Locked} The JWKS URI couldn't be resolved from the provider metadata. + {Locked} The server JSON Web Key set couldn't be retrieved. + {Locked} An error occurred while preparing the configuration request. Error: {0} Error description: {1} Error URI: {2} + {Locked} An error occurred while sending the configuration request. Error: {0} Error description: {1} Error URI: {2} + {Locked} An error occurred while extracting the configuration response. Error: {0} Error description: {1} Error URI: {2} + {Locked} An error occurred while handling the configuration response. Error: {0} Error description: {1} Error URI: {2} + {Locked} An error occurred while preparing the cryptography request. Error: {0} Error description: {1} Error URI: {2} + {Locked} An error occurred while sending the cryptography request. Error: {0} Error description: {1} Error URI: {2} + {Locked} An error occurred while extracting the cryptography response. Error: {0} Error description: {1} Error URI: {2} + {Locked} An error occurred while handling the cryptography response. Error: {0} Error description: {1} Error URI: {2} + {Locked} The token cannot be null or empty. + {Locked} An unknown error occurred while introspecting the token. + {Locked} An error occurred while preparing the introspection request. Error: {0} Error description: {1} Error URI: {2} + {Locked} An error occurred while sending the introspection request. Error: {0} Error description: {1} Error URI: {2} + {Locked} An error occurred while extracting the introspection response. Error: {0} Error description: {1} Error URI: {2} + {Locked} An error occurred while handling the introspection response. Error: {0} Error description: {1} Error URI: {2} + {Locked} The access token cannot be null or empty. + {Locked} An error occurred while validating the access token. Error: {0} Error description: {1} Error URI: {2} + {Locked} The OpenIddict ASP.NET Core validation handler cannot be registered as an authentication scheme. This may indicate that an instance of another handler was registered with the same scheme. + {Locked} The OpenIddict ASP.NET Core validation cannot be used as the default sign-in/sign-out handler. Make sure that neither DefaultSignInScheme nor DefaultSignOutScheme point to an instance of the OpenIddict ASP.NET Core validation handler. + {Locked} An unknown error occurred while retrieving the OpenIddict validation context. + {Locked} Generic token validation is not supported by the validation handler. + {Locked} No service provider was found in the OWIN context. For the OpenIddict validation services to work correctly, a per-request 'IServiceProvider' must be attached to the OWIN environment with the dictionary key 'System.IServiceProvider'. Note: when using a dependency injection container supporting middleware resolution (like Autofac), the 'app.UseOpenIddictValidation()' extension MUST NOT be called. + {Locked} The OpenIddict validation services cannot be resolved from the DI container. To register the validation services, use 'services.AddOpenIddict().AddValidation()'. + {Locked} The local server integration can only be used with direct validation. + {Locked} Authorization entry validation cannot be enabled when authorization storage is disabled in the OpenIddict server options. + {Locked} Token entry validation cannot be enabled when token storage is disabled in the OpenIddict server options. + {Locked} The System.Net.Http request cannot be resolved. + {Locked} An unknown error occurred while creating a System.Net.Http client. + {Locked} An unknown error occurred while sending a System.Net.Http request. + {Locked} The specified type is not supported. + {Locked} The value cannot be null or empty. + {Locked} The prompt cannot be null or empty. + {Locked} The response type cannot be null or empty. + {Locked} The scope cannot be null or empty. + {Locked} The destination cannot be null or empty. + {Locked} Destinations cannot be null or empty. + {Locked} Conflicting destinations for the claim '{0}' were specified. + {Locked} The claim type cannot be null or empty. + {Locked} The claim value cannot be null or empty. + {Locked} The audience cannot be null or empty. + {Locked} The presenter cannot be null or empty. + {Locked} The token type cannot be null or empty. + {Locked} The specified JSON element is not an object. + {Locked} The parameter name cannot be null or empty. + {Locked} A parameter with the same name already exists. + {Locked} The item name cannot be null or empty. + {Locked} The item index cannot be negative. + {Locked} The type of the parameter value is not supported. + {Locked} The identifier cannot be null or empty. + {Locked} The application identifier cannot be extracted. + {Locked} An error occurred while creating an expiration signal. + {Locked} The subject cannot be null or empty. + {Locked} The status cannot be null or empty. + {Locked} The type cannot be null or empty. + {Locked} The authorization identifier cannot be extracted. + {Locked} The scope name cannot be null or empty. + {Locked} Scope names cannot be null or empty. + {Locked} The scope identifier cannot be extracted. + {Locked} The token identifier cannot be extracted. + {Locked} The client secret hash cannot be set on the application entity. + {Locked} One or more validation error(s) occurred while trying to create a new application: + {Locked} An error occurred while trying to create a new application. + {Locked} The client type cannot be null or empty. + {Locked} The consent type cannot be null or empty. + {Locked} The permission name cannot be null or empty. + {Locked} The requirement name cannot be null or empty. + {Locked} Callback URLs cannot be null or empty. + {Locked} Callback URLs must be valid absolute URLs. + {Locked} One or more validation error(s) occurred while trying to update an existing application: + {Locked} The secret cannot be null or empty. + {Locked} The specified hash algorithm is not valid. + {Locked} The comparand cannot be null or empty. + {Locked} One or more validation error(s) occurred while trying to create a new authorization: + {Locked} An error occurred while trying to create a new authorization. + {Locked} One or more validation error(s) occurred while trying to update an existing authorization: + {Locked} One or more validation error(s) occurred while trying to create a new scope: + {Locked} An error occurred while trying to create a new scope. + {Locked} One or more validation error(s) occurred while trying to update an existing scope: + {Locked} One or more validation error(s) occurred while trying to create a new token: + {Locked} An error occurred while trying to create a new token + {Locked} One or more validation error(s) occurred while trying to update an existing token: + {Locked} No application store has been registered in the dependency injection container. To register the Entity Framework Core stores, reference the 'OpenIddict.EntityFrameworkCore' package and call 'services.AddOpenIddict().AddCore().UseEntityFrameworkCore()'. To register a custom store, create an implementation of 'IOpenIddictApplicationStore' and use 'services.AddOpenIddict().AddCore().AddApplicationStore()' to add it to the DI container. + {Locked} No authorization store has been registered in the dependency injection container. To register the Entity Framework Core stores, reference the 'OpenIddict.EntityFrameworkCore' package and call 'services.AddOpenIddict().AddCore().UseEntityFrameworkCore()'. To register a custom store, create an implementation of 'IOpenIddictAuthorizationStore' and use 'services.AddOpenIddict().AddCore().AddAuthorizationStore()' to add it to the DI container. + {Locked} No scope store has been registered in the dependency injection container. To register the Entity Framework Core stores, reference the 'OpenIddict.EntityFrameworkCore' package and call 'services.AddOpenIddict().AddCore().UseEntityFrameworkCore()'. To register a custom store, create an implementation of 'IOpenIddictScopeStore' and use 'services.AddOpenIddict().AddCore().AddScopeStore()' to add it to the DI container. + {Locked} No token store has been registered in the dependency injection container. To register the Entity Framework Core stores, reference the 'OpenIddict.EntityFrameworkCore' package and call 'services.AddOpenIddict().AddCore().UseEntityFrameworkCore()'. To register a custom store, create an implementation of 'IOpenIddictTokenStore' and use 'services.AddOpenIddict().AddCore().AddTokenStore()' to add it to the DI container. + {Locked} The specified type is invalid. + {Locked} The cache size cannot be less than 10. + {Locked} The specified application type is not compatible with the Entity Framework 6.x stores. When enabling the Entity Framework 6.x stores, make sure you use the built-in 'OpenIddictEntityFrameworkApplication' entity or a custom entity that inherits from the generic 'OpenIddictEntityFrameworkApplication' entity. + {Locked} No Entity Framework 6.x context was specified in the OpenIddict options. To configure the OpenIddict Entity Framework 6.x stores to use a specific 'DbContext', use 'options.UseEntityFramework().UseDbContext<TContext>()'. + {Locked} The specified authorization type is not compatible with the Entity Framework 6.x stores. When enabling the Entity Framework 6.x stores, make sure you use the built-in 'OpenIddictEntityFrameworkAuthorization' entity or a custom entity that inherits from the generic 'OpenIddictEntityFrameworkAuthorization' entity. + {Locked} The specified scope type is not compatible with the Entity Framework 6.x stores. When enabling the Entity Framework 6.x stores, make sure you use the built-in 'OpenIddictEntityFrameworkScope' entity or a custom entity that inherits from the generic 'OpenIddictEntityFrameworkScope' entity. + {Locked} The specified token type is not compatible with the Entity Framework 6.x stores. When enabling the Entity Framework 6.x stores, make sure you use the built-in 'OpenIddictEntityFrameworkToken' entity or a custom entity that inherits from the generic 'OpenIddictEntityFrameworkToken' entity. + {Locked} The application was concurrently updated and cannot be persisted in its current state. Reload the application from the database and retry the operation. + {Locked} An error occurred while trying to create a new application instance. Make sure that the application entity is not abstract and has a public parameterless constructor or create a custom application store that overrides 'InstantiateAsync()' to use a custom factory. + {Locked} The authorization was concurrently updated and cannot be persisted in its current state. Reload the authorization from the database and retry the operation. + {Locked} An error occurred while trying to create a new authorization instance. Make sure that the authorization entity is not abstract and has a public parameterless constructor or create a custom authorization store that overrides 'InstantiateAsync()' to use a custom factory. + {Locked} An error occurred while pruning authorizations. + {Locked} The application associated with the authorization cannot be found. + {Locked} The scope was concurrently updated and cannot be persisted in its current state. Reload the scope from the database and retry the operation. + {Locked} An error occurred while trying to create a new scope instance. Make sure that the scope entity is not abstract and has a public parameterless constructor or create a custom scope store that overrides 'InstantiateAsync()' to use a custom factory. + {Locked} The token was concurrently updated and cannot be persisted in its current state. Reload the token from the database and retry the operation. + {Locked} An error occurred while trying to create a new token instance. Make sure that the token entity is not abstract and has a public parameterless constructor or create a custom token store that overrides 'InstantiateAsync()' to use a custom factory. + {Locked} An error occurred while pruning tokens. + {Locked} The application associated with the token cannot be found. + {Locked} The authorization associated with the token cannot be found. + {Locked} The specified application type is not compatible with the Entity Framework Core stores. When enabling the Entity Framework Core stores, make sure you use the built-in 'OpenIddictEntityFrameworkCoreApplication' entity or a custom entity that inherits from the generic 'OpenIddictEntityFrameworkCoreApplication' entity. + {Locked} No Entity Framework Core context was specified in the OpenIddict options. To configure the OpenIddict Entity Framework Core stores to use a specific 'DbContext', use 'options.UseEntityFrameworkCore().UseDbContext<TContext>()'. + {Locked} The specified authorization type is not compatible with the Entity Framework Core stores. When enabling the Entity Framework Core stores, make sure you use the built-in 'OpenIddictEntityFrameworkCoreAuthorization' entity or a custom entity that inherits from the generic 'OpenIddictEntityFrameworkCoreAuthorization' entity. + {Locked} The specified scope type is not compatible with the Entity Framework Core stores. When enabling the Entity Framework Core stores, make sure you use the built-in 'OpenIddictEntityFrameworkCoreScope' entity or a custom entity that inherits from the generic 'OpenIddictEntityFrameworkCoreScope' entity. + {Locked} The specified token type is not compatible with the Entity Framework Core stores. When enabling the Entity Framework Core stores, make sure you use the built-in 'OpenIddictEntityFrameworkCoreToken' entity or a custom entity that inherits from the generic 'OpenIddictEntityFrameworkCoreToken' entity. + {Locked} The specified application type is not compatible with the MongoDB stores. When enabling the MongoDB stores, make sure you use the built-in 'OpenIddictMongoDbApplication' entity or a custom entity that inherits from the 'OpenIddictMongoDbApplication' entity. + {Locked} The specified authorization type is not compatible with the MongoDB stores. When enabling the MongoDB stores, make sure you use the built-in 'OpenIddictMongoDbAuthorization' entity or a custom entity that inherits from the 'OpenIddictMongoDbAuthorization' entity. + {Locked} The specified scope type is not compatible with the MongoDB stores. When enabling the MongoDB stores, make sure you use the built-in 'OpenIddictMongoDbScope' entity or a custom entity that inherits from the 'OpenIddictMongoDbScope' entity. + {Locked} The specified token type is not compatible with the MongoDB stores. When enabling the MongoDB stores, make sure you use the built-in 'OpenIddictMongoDbToken' entity or a custom entity that inherits from the 'OpenIddictMongoDbToken' entity. + {Locked} The collection name cannot be null or empty. + {Locked} No suitable MongoDB database service can be found. To configure the OpenIddict MongoDB stores to use a specific database, use 'services.AddOpenIddict().AddCore().UseMongoDb().UseDatabase()' or register an 'IMongoDatabase' in the dependency injection container in 'ConfigureServices()'. + {Locked} The second parameter must be a generic type definition. + {Locked} X.509 certificate generation is not supported on this platform. + {Locked} The token details cannot be found in the database. + {Locked} No suitable signing credentials could be found. + {Locked} The signing credentials algorithm is not valid. + {Locked} The code challenge method cannot be retrieved from the authorization code. + {Locked} The token usage of the JWT token is not supported. + {Locked} The type of the JWT token cannot be resolved or inferred. + {Locked} The type of the JWT token doesn't match the expected type. + {Locked} The configuration response was not correctly applied. To apply configuration responses, create a class implementing 'IOpenIddictServerHandler<ApplyConfigurationResponseContext>' and register it using 'services.AddOpenIddict().AddServer().AddEventHandler()'. + {Locked} No default application entity type was configured in the OpenIddict core options, which generally indicates that no application store was registered in the DI container. To register the Entity Framework Core stores, reference the 'OpenIddict.EntityFrameworkCore' package and call 'services.AddOpenIddict().AddCore().UseEntityFrameworkCore()'. + {Locked} No default authorization entity type was configured in the OpenIddict core options, which generally indicates that no authorization store was registered in the DI container. To register the Entity Framework Core stores, reference the 'OpenIddict.EntityFrameworkCore' package and call 'services.AddOpenIddict().AddCore().UseEntityFrameworkCore()'. + {Locked} No default scope entity type was configured in the OpenIddict core options, which generally indicates that no scope store was registered in the DI container. To register the Entity Framework Core stores, reference the 'OpenIddict.EntityFrameworkCore' package and call 'services.AddOpenIddict().AddCore().UseEntityFrameworkCore()'. + {Locked} No default token entity type was configured in the OpenIddict core options, which generally indicates that no token store was registered in the DI container. To register the Entity Framework Core stores, reference the 'OpenIddict.EntityFrameworkCore' package and call 'services.AddOpenIddict().AddCore().UseEntityFrameworkCore()'. + {Locked} The Entity Framework 6.x stores cannot be used with generic types. Consider creating non-generic classes derived from the default entities for the application, authorization, scope and token entities. + {Locked} The security token is missing. @@ -1112,7 +1387,7 @@ Consider creating non-generic classes derived from the default entities for the The specified token is not an access token. - The specified identity token hint is invalid. + The specified identity token is invalid. The specified authorization code has already been redeemed. @@ -1130,7 +1405,7 @@ Consider creating non-generic classes derived from the default entities for the The authorization has not been granted yet by the end user. - The authorization was denied by the resource owner. + The authorization was denied by the end user. The specified authorization code is no longer valid. @@ -1157,17 +1432,14 @@ Consider creating non-generic classes derived from the default entities for the The authorization associated with the token is no longer valid. - The token request was rejected by the authorization server. + The token request was rejected by the authentication server. - The user information access demand was rejected by the authorization server. + The user information access demand was rejected by the authentication server. The specified user code is no longer valid. - - The specified token is not valid. - The '{0}' parameter is not supported. @@ -1264,12 +1536,6 @@ Consider creating non-generic classes derived from the default entities for the A scope with the same name already exists. - - The '{0}' parameter is not valid for this client application. - - - The '{0}' parameter required for this client application is missing. - This client application is not allowed to use the token endpoint. @@ -1280,13 +1546,13 @@ Consider creating non-generic classes derived from the default entities for the The client application is not allowed to use the '{0}' scope. - The specified authorization code cannot be used without specifying a client identifier. + The specified authorization code cannot be used without sending a client identifier. - The specified device code cannot be used without specifying a client identifier. + The specified device code cannot be used without sending a client identifier. - The specified refresh token cannot be used without specifying a client identifier. + The specified refresh token cannot be used without sending a client identifier. The specified authorization code cannot be used by this client application. @@ -1298,10 +1564,10 @@ Consider creating non-generic classes derived from the default entities for the The specified refresh token cannot be used by this client application. - The specified '{0}' parameter doesn't match the client redirection endpoint the authorization code was initially sent to. + The specified '{0}' parameter doesn't match the client redirection address the authorization code was initially sent to. - The '{0}' parameter is uncalled for in this request. + The '{0}' parameter cannot be used when no '{1}' was specified in the authorization request. The '{0}' parameter is not valid in this context. @@ -1358,7 +1624,7 @@ Consider creating non-generic classes derived from the default entities for the The signature associated to the specified token is not valid. - This resource server is currently unavailable. Try again later. + This resource server is currently unavailable. The specified token doesn't contain any audience. @@ -1370,22 +1636,22 @@ Consider creating non-generic classes derived from the default entities for the The user represented by the token is not allowed to perform the requested action. - No issuer could be found in the discovery document. + No issuer could be found in the server configuration. - A discovery response containing an invalid issuer was returned. + A server configuration containing an invalid issuer was returned. - The issuer returned by the discovery endpoint is not valid. + The issuer returned in the server configuration is not valid. - No JWKS endpoint could be found in the discovery document. + No JWKS endpoint could be found in the server configuration. - A discovery response containing an invalid JWKS endpoint URL was returned. + A server configuration containing an invalid JWKS endpoint URL was returned. - A discovery response containing an invalid introspection endpoint URL was returned. + A server configuration containing an invalid introspection endpoint URL was returned. The JWKS document didn't contain a valid '{0}' node with at least one key. @@ -1400,19 +1666,19 @@ Consider creating non-generic classes derived from the default entities for the The mandatory '{0}' parameter couldn't be found in the introspection response. - The token was rejected by the remote authorization server. + The token was rejected by the remote authentication server. The '{0}' claim is malformed or isn't of the expected type. - An introspection response containing an invalid issuer was returned. + An introspection response containing a malformed issuer was returned. The issuer returned in the introspection response is not valid. - The type of the introspection token doesn't match the expected type. + The type of the introspected token doesn't match the expected type. An application with the same client identifier already exists. @@ -1446,582 +1712,773 @@ Consider creating non-generic classes derived from the default entities for the The '{0}' parameter shouldn't be null or empty at this point. + {Locked} The separators collection shouldn't be null or empty. + {Locked} The value string shouldn't be null or empty. + {Locked} RSA.ExportParameters() shouldn't return invalid values. + {Locked} ECDsa.ExportParameters() shouldn't return invalid values. + {Locked} ECDsa.ExportParameters() shouldn't return an unnamed curve. + {Locked} The principal shouldn't be null at this point. + {Locked} The response shouldn't be null at this point. + {Locked} The request shouldn't be null at this point. + {Locked} The token type shouldn't be null or empty. + {Locked} The token shouldn't be null or empty at this point. + {Locked} An error occurred while validating the token '{Token}'. + {Locked} The token '{Token}' was successfully validated and the following claims could be extracted: {Claims}. + {Locked} The token '{Identifier}' has already been redeemed. + {Locked} The token '{Identifier}' is not active yet. + {Locked} The token '{Identifier}' was marked as rejected. + {Locked} The token '{Identifier}' was no longer valid. + {Locked} The authorization '{Identifier}' was no longer valid. + {Locked} An ad hoc authorization was automatically created and associated with an unknown application: {Identifier}. + {Locked} An ad hoc authorization was automatically created and associated with the '{ClientId}' application: {Identifier}. + {Locked} '{Claim}' was excluded from the access token claims. + {Locked} The access token scopes will be limited to the scopes requested by the client application: {Scopes}. + {Locked} '{Claim}' was excluded from the identity token claims. + {Locked} The token entry for access token '{Identifier}' was successfully created. + {Locked} The access token '{Identifier}' was successfully created: {Payload}. The principal used to create the token contained the following claims: {Claims}. + {Locked} The token entry for access token '{Identifier}' was successfully converted to a reference token with the identifier '{ReferenceId}'. + {Locked} The token entry for authorization code '{Identifier}' was successfully created. + {Locked} The authorization code '{Identifier}' was successfully created: {Payload}. The principal used to create the token contained the following claims: {Claims}. + {Locked} The token entry for authorization code '{Identifier}' was successfully converted to a reference token with the identifier '{ReferenceId}'. + {Locked} The token entry for device code '{Identifier}' was successfully created. + {Locked} The device code '{Identifier}' was successfully created: {Payload}. The principal used to create the token contained the following claims: {Claims}. + {Locked} The token entry for device code '{Identifier}' was successfully converted to a reference token with the identifier '{ReferenceId}'. + {Locked} The reference token entry for device code '{Identifier}' was successfully updated'. + {Locked} The token entry for refresh token '{Identifier}' was successfully created. + {Locked} The refresh token '{Identifier}' was successfully created: {Payload}. The principal used to create the token contained the following claims: {Claims}. + {Locked} The token entry for refresh token '{Identifier}' was successfully converted to a reference token with the identifier '{ReferenceId}'. + {Locked} The token entry for user code '{Identifier}' was successfully created. + {Locked} The user code '{Identifier}' was successfully created: {Payload}. The principal used to create the token contained the following claims: {Claims}. + {Locked} The token entry for user code '{Identifier}' was successfully converted to a reference token with the identifier '{ReferenceId}'. + {Locked} The token entry for identity token '{Identifier}' was successfully created. + {Locked} The identity token '{Identifier}' was successfully created: {Payload}. The principal used to create the token contained the following claims: {Claims}. + {Locked} The authorization request was successfully extracted: {Request}. + {Locked} The authorization request was successfully validated. + {Locked} The authorization request was rejected because it contained an unsupported parameter: {Parameter}. + {Locked} The authorization request was rejected because the mandatory '{Parameter}' parameter was missing. + {Locked} The authorization request was rejected because the '{Parameter}' parameter wasn't a valid absolute URL: {RedirectUri}. + {Locked} The authorization request was rejected because the '{Parameter}' contained a URL fragment: {RedirectUri}. + {Locked} The authorization request was rejected because the '{ResponseType}' response type is not supported. + {Locked} The authorization request was rejected because the 'response_type'/'response_mode' combination was invalid: {ResponseType} ; {ResponseMode}. + {Locked} The authorization request was rejected because the '{ResponseMode}' response mode is not supported. + {Locked} The authorization request was rejected because the '{Scope}' scope was missing. + {Locked} The authorization request was rejected because an invalid prompt parameter was specified. + {Locked} The authorization request was rejected because the specified code challenge method was not supported. + {Locked} The authorization request was rejected because the response type was not compatible with 'code_challenge'/'code_challenge_method'. + {Locked} The authorization request was rejected because the specified response type was not compatible with PKCE. + {Locked} The authorization request was rejected because the client application was not found: '{ClientId}'. + {Locked} The authorization request was rejected because the confidential application '{ClientId}' was not allowed to retrieve an access token from the authorization endpoint. + {Locked} The authorization request was rejected because the redirect_uri was invalid: '{RedirectUri}'. + {Locked} The authentication request was rejected because invalid scopes were specified: {Scopes}. + {Locked} The authorization request was rejected because the application '{ClientId}' was not allowed to use the authorization endpoint. + {Locked} The authorization request was rejected because the application '{ClientId}' was not allowed to use the authorization code flow. + {Locked} The authorization request was rejected because the application '{ClientId}' was not allowed to use the implicit flow. + {Locked} The authorization request was rejected because the application '{ClientId}' was not allowed to use the hybrid flow. + {Locked} The authorization request was rejected because the application '{ClientId}' was not allowed to use the '{Scope}' scope. + {Locked} The request address matched a server endpoint: {Endpoint}. + {Locked} The device request was successfully extracted: {Request}. + {Locked} The device request was successfully validated. + {Locked} The device request was rejected because the mandatory '{Parameter}' parameter was missing. + {Locked} The device request was rejected because invalid scopes were specified: {Scopes}. + {Locked} The device request was rejected because the client application was not found: '{ClientId}'. + {Locked} The device request was rejected because the public application '{ClientId}' was not allowed to send a client secret. + {Locked} The device request was rejected because the confidential or hybrid application '{ClientId}' didn't specify a client secret. + {Locked} The device request was rejected because the confidential or hybrid application '{ClientId}' didn't specify valid client credentials. + {Locked} The device request was rejected because the application '{ClientId}' was not allowed to use the device endpoint. + {Locked} The device request was rejected because the application '{ClientId}' was not allowed to use the scope {Scope}. + {Locked} The verification request was successfully extracted: {Request}. + {Locked} The verification request was successfully validated. + {Locked} The configuration request was successfully extracted: {Request}. + {Locked} The configuration request was successfully validated. + {Locked} The cryptography request was successfully extracted: {Request}. + {Locked} The cryptography request was successfully validated. + {Locked} A JSON Web Key was excluded from the key set because it didn't contain the mandatory '{Parameter}' parameter. + {Locked} An unsupported signing key of type '{Type}' was ignored and excluded from the key set. Only RSA and ECDSA asymmetric security keys can be exposed via the JWKS endpoint. + {Locked} An unsupported signing key of type '{Type}' was ignored and excluded from the key set. Only RSA asymmetric security keys can be exposed via the JWKS endpoint. + {Locked} A signing key of type '{Type}' was ignored because its RSA public parameters couldn't be extracted. + {Locked} A signing key of type '{Type}' was ignored because its EC public parameters couldn't be extracted. + {Locked} The token request was successfully extracted: {Request}. + {Locked} The token request was successfully validated. + {Locked} The token request was rejected because the mandatory '{Parameter}' parameter was missing. + {Locked} The token request was rejected because the '{GrantType}' grant type is not supported. + {Locked} The token request was rejected because the resource owner credentials were missing. + {Locked} The token request was rejected because invalid scopes were specified: {Scopes}. + {Locked} The token request was rejected because the client application was not found: '{ClientId}'. + {Locked} The token request was rejected because the public client application '{ClientId}' was not allowed to use the client credentials grant. + {Locked} The token request was rejected because the public application '{ClientId}' was not allowed to send a client secret. + {Locked} The token request was rejected because the confidential or hybrid application '{ClientId}' didn't specify a client secret. + {Locked} The token request was rejected because the confidential or hybrid application '{ClientId}' didn't specify valid client credentials. + {Locked} The token request was rejected because the application '{ClientId}' was not allowed to use the token endpoint. + {Locked} The token request was rejected because the application '{ClientId}' was not allowed to use the specified grant type: {GrantType}. + {Locked} The token request was rejected because the application '{ClientId}' was not allowed to request the '{Scope}' scope. + {Locked} The token request was rejected because the application '{ClientId}' was not allowed to use the scope {Scope}. + {Locked} The token request was rejected because the client identifier of the application was not available and could not be compared to the presenters list stored in the authorization code, the device code or the refresh token. + {Locked} The token request was rejected because the authorization code, the device code or the refresh token was issued to a different client application. + {Locked} The token request was rejected because the '{Parameter}' parameter didn't correspond to the expected value. + {Locked} The token request was rejected because a '{0}' parameter was presented with an authorization code to which no code challenge was attached when processing the initial authorization request. + {Locked} The token request was rejected because the '{Parameter}' parameter was not allowed. + {Locked} The token request was rejected because the '{Parameter}' parameter was not valid. + {Locked} The introspection request was successfully extracted: {Request}. + {Locked} The introspection request was successfully validated. + {Locked} The introspection request was rejected because the mandatory '{Parameter}' parameter was missing. + {Locked} The introspection request was rejected because the client application was not found: '{ClientId}'. + {Locked} The introspection request was rejected because the public application '{ClientId}' was not allowed to send a client secret. + {Locked} The introspection request was rejected because the confidential or hybrid application '{ClientId}' didn't specify a client secret. + {Locked} The introspection request was rejected because the confidential or hybrid application '{ClientId}' didn't specify valid client credentials. + {Locked} The introspection request was rejected because the application '{ClientId}' was not allowed to use the introspection endpoint. + {Locked} The introspection request was rejected because the received token was of an unsupported type. + {Locked} The introspection request was rejected because the authorization code was issued to a different client. + {Locked} The introspection request was rejected because the access token was issued to a different client or for another resource server. + {Locked} The introspection request was rejected because the identity token was issued to a different client. + {Locked} The introspection request was rejected because the refresh token was issued to a different client. + {Locked} The revocation request was successfully extracted: {Request}. + {Locked} The revocation request was successfully validated. + {Locked} The revocation request was rejected because the mandatory '{Parameter}' parameter was missing. + {Locked} The revocation request was rejected because the client application was not found: '{ClientId}'. + {Locked} The revocation request was rejected because the public application '{ClientId}' was not allowed to send a client secret. + {Locked} The revocation request was rejected because the confidential or hybrid application '{ClientId}' didn't specify a client secret. + {Locked} The revocation request was rejected because the confidential or hybrid application '{ClientId}' didn't specify valid client credentials. + {Locked} The revocation request was rejected because the application '{ClientId}' was not allowed to use the revocation endpoint. + {Locked} The revocation request was rejected because the received token was of an unsupported type. + {Locked} The revocation request was rejected because the authorization code was issued to a different client. + {Locked} The revocation request was rejected because the access token was issued to a different client or for another resource server. + {Locked} The revocation request was rejected because the identity token was issued to a different client. + {Locked} The revocation request was rejected because the refresh token was issued to a different client. + {Locked} The revocation request was rejected because the token had no internal identifier. + {Locked} The token '{Identifier}' was not revoked because it couldn't be found. + {Locked} The logout request was successfully extracted: {Request}. + {Locked} The logout request was successfully validated. + {Locked} The logout request was rejected because the '{Parameter}' parameter wasn't a valid absolute URL: {PostLogoutRedirectUri}. + {Locked} The logout request was rejected because the '{Parameter}' contained a URL fragment: {PostLogoutRedirectUri}. + {Locked} The logout request was rejected because the specified post_logout_redirect_uri was invalid: {PostLogoutRedirectUri}. + {Locked} The userinfo request was successfully extracted: {Request}. + {Locked} The userinfo request was successfully validated. + {Locked} The userinfo request was rejected because the mandatory '{Parameter}' parameter was missing. + {Locked} An exception was thrown by {HandlerName} while handling the {EventName} event. + {Locked} The event {EventName} was successfully processed by {HandlerName}. + {Locked} The event {EventName} was marked as handled by {HandlerName}. + {Locked} The event {EventName} was marked as skipped by {HandlerName}. + {Locked} The event {EventName} was marked as rejected by {HandlerName}. + {Locked} The request was rejected because an invalid HTTP method was specified: {Method}. + {Locked} The request was rejected because the mandatory '{Header}' header was missing. + {Locked} The request was rejected because an invalid '{Header}' header was specified: {Value}. + {Locked} The request was rejected because multiple client credentials were specified. + {Locked} The response was successfully returned as a challenge response: {Response}. + {Locked} The response was successfully returned as a JSON document: {Response}. + {Locked} The response was successfully returned as a plain-text document: {Response}. + {Locked} The response was successfully returned as a 302 response. + {Locked} The response was successfully returned as an empty 200 response. + {Locked} The authorization request was rejected because an unknown or invalid '{Parameter}' was specified. + {Locked} The authorization response was successfully returned to '{RedirectUri}' using the form post response mode: {Response}. + {Locked} The authorization response was successfully returned to '{RedirectUri}' using the query response mode: {Response}. + {Locked} The authorization response was successfully returned to '{RedirectUri}' using the fragment response mode: {Response}. + {Locked} The logout request was rejected because an unknown or invalid '{Parameter}' was specified. + {Locked} The logout response was successfully returned to '{PostLogoutRedirectUri}': {Response}. + {Locked} The ASP.NET Core Data Protection token '{Token}' was successfully validated and the following claims could be extracted: {Claims}. + {Locked} An exception occured while deserializing the token '{Token}'. + {Locked} The token '{Token}' was successfully introspected and the following claims could be extracted: {Claims}. + {Locked} An error occurred while introspecting the token. + {Locked} The authentication demand was rejected because the token was expired. + {Locked} The authentication demand was rejected because the token had no audience attached. + {Locked} The authentication demand was rejected because the token had no valid audience. + {Locked} Client authentication cannot be enforced for public applications. + {Locked} Client authentication failed for {Client} because no client secret was associated with the application. + {Locked} Client authentication failed for {Client}. + {Locked} Client validation failed because '{RedirectUri}' was not a valid redirect_uri for {Client}. + {Locked} An error occurred while trying to verify a client secret. This may indicate that the hashed entry is corrupted or malformed. + {Locked} The authorization '{Identifier}' was successfully revoked. + {Locked} A concurrency exception occurred while trying to revoke the authorization '{Identifier}'. + {Locked} An exception occurred while trying to revoke the authorization '{Identifier}'. + {Locked} The expiration date of the refresh token '{Identifier}' was successfully updated: {Date}. + {Locked} The expiration date of the refresh token '{Identifier}' was successfully removed. + {Locked} A concurrency exception occurred while trying to update the expiration date of the token '{Identifier}'. + {Locked} An exception occurred while trying to update the expiration date of the token '{Identifier}'. + {Locked} The token '{Identifier}' was successfully marked as redeemed. + {Locked} A concurrency exception occurred while trying to redeem the token '{Identifier}'. + {Locked} An exception occurred while trying to redeem the token '{Identifier}'. + {Locked} The token '{Identifier}' was successfully marked as rejected. + {Locked} A concurrency exception occurred while trying to reject the token '{Identifier}'. + {Locked} An exception occurred while trying to reject the token '{Identifier}'. + {Locked} The token '{Identifier}' was successfully revoked. + {Locked} A concurrency exception occurred while trying to revoke the token '{Identifier}'. + {Locked} An exception occurred while trying to revoke the token '{Identifier}'. + {Locked} \ No newline at end of file diff --git a/src/OpenIddict.Abstractions/Resources/xlf/OpenIddictResources.fr.xlf b/src/OpenIddict.Abstractions/Resources/xlf/OpenIddictResources.fr.xlf new file mode 100644 index 00000000..5799a270 --- /dev/null +++ b/src/OpenIddict.Abstractions/Resources/xlf/OpenIddictResources.fr.xlf @@ -0,0 +1,592 @@ + + + + + + The security token is missing. + Le jeton de sécurité est manquant. + + + + The specified authorization code is invalid. + Le code d'autorisation spécifié n'est pas valide. + + + + The specified device code is invalid. + Le code d'appareil spécifié n'est pas valide. + + + + The specified refresh token is invalid. + Le jeton de rafraîchissement spécifié n'est pas valide. + + + + The specified token is invalid. + Le jeton spécifié n'est pas valide. + + + + The specified token is not an authorization code. + Le jeton spécifié n'est pas un code d'autorisation. + + + + The specified token is not an device code. + Le jeton spécifié n'est pas un code d'appareil. + + + + The specified token is not a refresh token. + Le jeton spécifié n'est pas un jeton d'actualisation. + + + + The specified token is not an access token. + Le jeton spécifié n'est pas un jeton d'accès. + + + + The specified identity token is invalid. + Le jeton d'identité spécifié n'est pas valide. + + + + The specified authorization code has already been redeemed. + Le jeton d'autorisation spécifié a déjà été échangé. + + + + The specified device code has already been redeemed. + Le jeton d'appareil spécifié a déjà été échangé. + + + + The specified refresh token has already been redeemed. + Le jeton de rafraîchissement spécifié a déjà été échangé. + + + + The specified token has already been redeemed. + Le jeton spécifié a déjà été échangé. + + + + The authorization has not been granted yet by the end user. + L'autorisation n'a pas encore été accordée par l'utilisateur final. + + + + The authorization was denied by the end user. + L'autorisation a été refusée par l'utilisateur final. + + + + The specified authorization code is no longer valid. + Le code d'autorisation spécifié n'est plus valide. + + + + The specified device code is no longer valid. + Le code d'appareil spécifié n'est plus valide. + + + + The specified refresh token is no longer valid. + Le jeton d'actualisation spécifié n'est plus valide. + + + + The specified token is no longer valid. + Le jeton spécifié n'est plus valide. + + + + The authorization associated with the authorization code is no longer valid. + L'autorisation associée au code d'autorisation n'est plus valide. + + + + The authorization associated with the device code is no longer valid. + L'autorisation associée au code d'appareil n'est plus valide. + + + + The authorization associated with the refresh token is no longer valid. + L'autorisation associée au jeton d'actualisation n'est plus valide. + + + + The authorization associated with the token is no longer valid. + L'autorisation associée au jeton n'est plus valide. + + + + The token request was rejected by the authentication server. + La demande de jeton a été rejetée par le serveur d'authentification. + + + + The user information access demand was rejected by the authentication server. + La demande d'information utilisateur a été rejetée par le serveur d'authentification. + + + + The specified user code is no longer valid. + Le code utilisateur spécifié n'est plus valide. + + + + The '{0}' parameter is not supported. + Le paramètre '{0}' n'est pas supporté. + + + + The mandatory '{0}' parameter is missing. + Le paramètre '{0}' obligatoire est manquant. + + + + The '{0}' parameter must be a valid absolute URL. + Le paramètre '{0}' doit être une URL valide et absolue. + + + + The '{0}' parameter must not include a fragment. + Le paramètre '{0}' ne doit pas comporter de fragment. + + + + The specified '{0}' is not supported. + Le '{0}' spécifié n'est pas supporté. + + + + The specified '{0}'/'{1}' combination is invalid. + La combinaison '{0}'/'{1}' spécifiée n'est pas valide. + + + + The mandatory '{0}' scope is missing. + La portée '{0}' obligatoire est manquante. + + + + The '{0}' scope is not allowed. + La portée '{0}' n'est pas autorisée. + + + + The client identifier cannot be null or empty. + L'identifiant client ne peut pas être null ou vide. + + + + The '{0}' parameter cannot be used without '{1}'. + Le paramètre '{0}' ne peut pas être utilisé sans '{1}'. + + + + The status cannot be null or empty. + Le statut ne peut pas être null ou vide. + + + + Scopes cannot be null or empty. + Les portées ne peuvent pas être null ou vides. + + + + The '{0}' and '{1}' parameters can only be used with a response type containing '{2}'. + Les paramètres '{0}' et '{1}' ne peuvent être utilisés qu'avec un type de réponse contenant '{2}'. + + + + The specified '{0}' is not allowed when using PKCE. + Le '{0}' spécifié n'est pas autorisé lorsque PKCE est utilisé. + + + + Scopes cannot contain spaces. + Les portées ne peuvent pas contenir d'espace. + + + + The specified '{0}' is not valid for this client application. + Le '{0}' spécifié n'est pas valide pour cette application cliente. + + + + The scope name cannot be null or empty. + Le nom de la portée ne peut pas être null ou vide. + + + + The scope name cannot contain spaces. + Le nom de la portée ne peut pas contenir d'espace. + + + + This client application is not allowed to use the authorization endpoint. + Cette application cliente n'est pas autorisée à utiliser le point de terminaison d'autorisation. + + + + The client application is not allowed to use the authorization code flow. + Cette application cliente n'est pas autorisée à utiliser le flux d'autorisation par code. + + + + The client application is not allowed to use the implicit flow. + Cette application cliente n'est pas autorisée à utiliser le flux implicite. + + + + The client application is not allowed to use the hybrid flow. + Cette application cliente n'est pas autorisée à utiliser le flux hybride. + + + + This client application is not allowed to use the specified scope. + Cette application cliente n'est pas autorisée à utiliser la portée spécifiée. + + + + The specified '{0}' is invalid. + Le '{0}' spécifié n'est pas valide. + + + + The '{0}' parameter is not valid for this client application. + Le paramètre '{0}' n'est pas valide pour cette application cliente. + + + + The '{0}' parameter required for this client application is missing. + Le paramètre '{0}' obligatoire pour cette application cliente est manquant. + + + + The specified client credentials are invalid. + Les identifiants client spécifiés ne sont pas valides. + + + + This client application is not allowed to use the device endpoint. + Cette application cliente n'est pas autorisée à utiliser le point de terminaison d'appareil. + + + + The '{0}' and '{1}' parameters are required when using the client credentials grant. + Les paramètres '{0}' et '{1}' sont requis lors que l'accès par identifiants client est utilisé. + + + + The '{0}' parameter is required when using the device code grant. + Le paramètre '{0}' obligatoire est requis en utilisant l'accès par code d'appareil. + + + + The mandatory '{0}' and/or '{1}' parameters are missing. + Les paramètres obligatoires '{0}' et/ou '{1}' sont manquants. + + + + A scope with the same name already exists. + Une portée avec le même nom existe déjà. + + + + This client application is not allowed to use the token endpoint. + Cette application cliente n'est pas autorisée à utiliser le point de terminaison d'obtention de jeton. + + + + This client application is not allowed to use the specified grant type. + Cette application cliente n'est pas autorisée à utiliser le type d'accès spécifié. + + + + The client application is not allowed to use the '{0}' scope. + Cette application cliente n'est pas autorisée à utiliser la portée '{0}'. + + + + The specified authorization code cannot be used without sending a client identifier. + Le code d'autorisation spécifié ne peut pas être utilisé sans envoyer d'identifiant client. + + + + The specified device code cannot be used without sending a client identifier. + Le code d'appareil spécifié ne peut pas être utilisé sans envoyer d'identifiant client. + + + + The specified refresh token cannot be used without sending a client identifier. + Le jeton de rafraîchissement spécifié ne peut pas être utilisé sans envoyer d'identifiant client. + + + + The specified authorization code cannot be used by this client application. + Le code d'autorisation spécifié ne peut pas être utilisé par cette application cliente. + + + + The specified device code cannot be used by this client application. + Le code d'appareil spécifié ne peut pas être utilisé par cette application cliente. + + + + The specified refresh token cannot be used by this client application. + Le jeton de rafraîchissement spécifié ne peut pas être utilisé par cette application cliente. + + + + The specified '{0}' parameter doesn't match the client redirection address the authorization code was initially sent to. + Le paramètre '{0}' spécifié ne correspond pas à l'adresse de redirection client à laquelle le code d'autorisation a été initialement envoyé. + + + + The '{0}' parameter cannot be used when no '{1}' was specified in the authorization request. + Le paramètre '{0}' ne peut pas être utilisé lorsqu'aucun '{1}' n'a été spécifié dans la demande d'autorisation. + + + + The '{0}' parameter is not valid in this context. + Le paramètre '{0}' n'est pas valide dans ce contexte. + + + + This client application is not allowed to use the introspection endpoint. + Cette application cliente n'est pas autorisée à utiliser le point de terminaison d'introspection. + + + + The specified token cannot be introspected. + Le jeton spécifié ne peut pas être introspecté. + + + + The client application is not allowed to introspect the specified token. + L'application cliente n'est pas autorisée à introspecter le jeton spécifié. + + + + This client application is not allowed to use the revocation endpoint. + Cette application cliente n'est pas autorisée à utiliser le point de terminaison de révocation. + + + + This token cannot be revoked. + Ce jeton ne peut pas être révoqué. + + + + The client application is not allowed to revoke the specified token. + Cette application cliente n'est pas autorisée à révoquer le jeton spécifié. + + + + The mandatory '{0}' header is missing. + L'en-tête '{0}' obligatoire est manquant. + + + + The specified '{0}' header is invalid. + L'en-tête '{0}' spécifié n'est pas valide. + + + + This server only accepts HTTPS requests. + Ce serveur n'accepte que des requêtes HTTPS. + + + + The specified HTTP method is not valid. + La méthode HTTP spécifiée n'est pas valide. + + + + A token with the same reference identifier already exists. + Un jeton avec le même identifiant par référence existe déjà. + + + + The token type cannot be null or empty. + Le type de jeton ne peut pas être null ou vide. + + + + Multiple client credentials cannot be specified. + Plusieurs identifiants client ne peuvent pas être spécifiés. + + + + The issuer associated to the specified token is not valid. + L'émetteur associé au jeton spécifié n'est pas valide. + + + + The specified token is not of the expected type. + Le jeton spécifié n'est pas du type attendu. + + + + The signing key associated to the specified token was not found. + La clé de signature associée au jeton spécifié n'a pas été trouvée. + + + + The signature associated to the specified token is not valid. + La signature associée au jeton spécifiée n'est pas valid. + + + + This resource server is currently unavailable. + Ce serveur de ressource est actuellement indisponible. + + + + The specified token doesn't contain any audience. + Le jeton spécifié ne contient aucune audience. + + + + The specified token cannot be used with this resource server. + Le jeton spécifié ne peut pas être utilisé par ce serveur de ressource. + + + + The user represented by the token is not allowed to perform the requested action. + L'utilisateur représenté par le jeton n'est pas autorisé à exécuter l'action demandée. + + + + No issuer could be found in the server configuration. + Aucun émetteur n'a pu être trouvé dans la configuration du serveur. + + + + A server configuration containing an invalid issuer was returned. + Une configuration serveur contenant un émetteur non valide a été retournée. + + + + The issuer returned in the server configuration is not valid. + L'émetteur retourné dans la configuration du serveur n'est pas valide. + + + + No JWKS endpoint could be found in the server configuration. + Aucun point de terminaison JWKS n'a pu être trouvé dans la configuration du serveur. + + + + A server configuration containing an invalid JWKS endpoint URL was returned. + Une configuration serveur contenant une URL invalide pour le point de terminaison JWKS a été retournée. + + + + A server configuration containing an invalid introspection endpoint URL was returned. + Une configuration serveur contenant une URL invalide pour le point de terminaison d'introspection a été retournée. + + + + The JWKS document didn't contain a valid '{0}' node with at least one key. + Le document JWKS ne contenait pas de nœud '{0}' valide comportant au moins une clé. + + + + A JWKS response containing an unsupported key was returned. + Une réponse JWKS contenant une clé non supportée a été retournée. + + + + A JWKS response containing an invalid key was returned. + Une réponse JWKS contenant une clé non valide a été retournée. + + + + The mandatory '{0}' parameter couldn't be found in the introspection response. + Le paramètre '{0}' obligatoire n'a pu être trouvé dans la réponse d'introspection. + + + + The token was rejected by the remote authentication server. + Le jeton a été rejeté par le serveur d'authentification distant. + + + + The '{0}' claim is malformed or isn't of the expected type. + La revendication '{0}' est malformée ou n'est pas du type attendu. + + + + An introspection response containing a malformed issuer was returned. + Une réponse d'introspection contenant un émetteur malformé a été retournée. + + + + The issuer returned in the introspection response is not valid. + L'émetteur retourné dans la réponse d'introspection n'est pas valide. + + + + The type of the introspected token doesn't match the expected type. + Le type du jeton introspecté ne correspond pas au type attendu. + + + + An application with the same client identifier already exists. + Une application avec le même identifiant client existe déjà. + + + + Only confidential, hybrid or public applications are supported by the default application manager. + Seules les applications confidentielles, hybrides ou publiques sont supportées par le gestionnaire d'application par défaut. + + + + The client secret cannot be null or empty for a confidential application. + Le secret client ne peut pas être null ou vide pour une application confidentielle. + + + + A client secret cannot be associated with a public application. + Un secret client ne peut pas être associé à une application publique. + + + + Callback URLs cannot contain a fragment. + Les URLs de rappel ne peuvent pas contenir de fragment. + + + + The authorization type cannot be null or empty. + Le type d'autorisation ne peut pas être null ou vide. + + + + The specified authorization type is not supported by the default token manager. + Le type d'autorisation spécifié n'est pas supporté par le gestionnaire de jeton par défaut. + + + + The client type cannot be null or empty. + Le type de client ne peut pas être null ou vide. + + + + Callback URLs cannot be null or empty. + Les URLs de rappel ne peuvent pas être null ou vides. + + + + Callback URLs must be valid absolute URLs. + Les URLs de rappel doit être des URLs valides et absolues. + + + + + \ No newline at end of file diff --git a/src/OpenIddict.Server.DataProtection/OpenIddictServerDataProtectionHandlers.cs b/src/OpenIddict.Server.DataProtection/OpenIddictServerDataProtectionHandlers.cs index c48e6afb..043dca36 100644 --- a/src/OpenIddict.Server.DataProtection/OpenIddictServerDataProtectionHandlers.cs +++ b/src/OpenIddict.Server.DataProtection/OpenIddictServerDataProtectionHandlers.cs @@ -102,7 +102,7 @@ namespace OpenIddict.Server.DataProtection OpenIddictServerEndpointType.Token => Errors.InvalidGrant, _ => Errors.InvalidToken }, - description: context.Localizer[SR.ID3027]); + description: context.Localizer[SR.ID3004]); return default; } diff --git a/src/OpenIddict.Server/OpenIddictServerHandlers.Authentication.cs b/src/OpenIddict.Server/OpenIddictServerHandlers.Authentication.cs index 8e9d3973..8db9b064 100644 --- a/src/OpenIddict.Server/OpenIddictServerHandlers.Authentication.cs +++ b/src/OpenIddict.Server/OpenIddictServerHandlers.Authentication.cs @@ -1412,7 +1412,7 @@ namespace OpenIddict.Server context.Reject( error: Errors.InvalidRequest, - description: context.Localizer[SR.ID3029, Parameters.CodeChallenge]); + description: context.Localizer[SR.ID3054, Parameters.CodeChallenge]); return; } diff --git a/src/OpenIddict.Server/OpenIddictServerHandlers.Exchange.cs b/src/OpenIddict.Server/OpenIddictServerHandlers.Exchange.cs index 8cd200bb..ebfea6eb 100644 --- a/src/OpenIddict.Server/OpenIddictServerHandlers.Exchange.cs +++ b/src/OpenIddict.Server/OpenIddictServerHandlers.Exchange.cs @@ -820,7 +820,7 @@ namespace OpenIddict.Server context.Reject( error: Errors.InvalidClient, - description: context.Localizer[SR.ID3061, Parameters.ClientSecret]); + description: context.Localizer[SR.ID3053, Parameters.ClientSecret]); return; } @@ -835,7 +835,7 @@ namespace OpenIddict.Server context.Reject( error: Errors.InvalidClient, - description: context.Localizer[SR.ID3062, Parameters.ClientSecret]); + description: context.Localizer[SR.ID3054, Parameters.ClientSecret]); return; } @@ -1159,7 +1159,7 @@ namespace OpenIddict.Server context.Reject( error: Errors.InvalidRequest, - description: context.Localizer[SR.ID3029, Parameters.CodeVerifier]); + description: context.Localizer[SR.ID3054, Parameters.CodeVerifier]); return; } @@ -1438,7 +1438,7 @@ namespace OpenIddict.Server context.Reject( error: Errors.InvalidRequest, - description: context.Localizer[SR.ID3073, Parameters.CodeVerifier]); + description: context.Localizer[SR.ID3073, Parameters.CodeVerifier, Parameters.CodeChallenge]); return default; } diff --git a/src/OpenIddict.Server/OpenIddictServerHandlers.Introspection.cs b/src/OpenIddict.Server/OpenIddictServerHandlers.Introspection.cs index 3ab2914a..f9c9437f 100644 --- a/src/OpenIddict.Server/OpenIddictServerHandlers.Introspection.cs +++ b/src/OpenIddict.Server/OpenIddictServerHandlers.Introspection.cs @@ -517,7 +517,7 @@ namespace OpenIddict.Server context.Reject( error: Errors.InvalidClient, - description: context.Localizer[SR.ID3061, Parameters.ClientSecret]); + description: context.Localizer[SR.ID3053, Parameters.ClientSecret]); return; } @@ -532,7 +532,7 @@ namespace OpenIddict.Server context.Reject( error: Errors.InvalidClient, - description: context.Localizer[SR.ID3062, Parameters.ClientSecret]); + description: context.Localizer[SR.ID3054, Parameters.ClientSecret]); return; } diff --git a/src/OpenIddict.Server/OpenIddictServerHandlers.Revocation.cs b/src/OpenIddict.Server/OpenIddictServerHandlers.Revocation.cs index 6264417c..e661341a 100644 --- a/src/OpenIddict.Server/OpenIddictServerHandlers.Revocation.cs +++ b/src/OpenIddict.Server/OpenIddictServerHandlers.Revocation.cs @@ -463,7 +463,7 @@ namespace OpenIddict.Server context.Reject( error: Errors.InvalidClient, - description: context.Localizer[SR.ID3061, Parameters.ClientSecret]); + description: context.Localizer[SR.ID3053, Parameters.ClientSecret]); return; } @@ -478,7 +478,7 @@ namespace OpenIddict.Server context.Reject( error: Errors.InvalidClient, - description: context.Localizer[SR.ID3062, Parameters.ClientSecret]); + description: context.Localizer[SR.ID3054, Parameters.ClientSecret]); return; } diff --git a/src/OpenIddict.Server/OpenIddictServerHandlers.cs b/src/OpenIddict.Server/OpenIddictServerHandlers.cs index 7ff7c1ea..274cd095 100644 --- a/src/OpenIddict.Server/OpenIddictServerHandlers.cs +++ b/src/OpenIddict.Server/OpenIddictServerHandlers.cs @@ -465,7 +465,7 @@ namespace OpenIddict.Server (SecurityTokenInvalidTypeException _, OpenIddictServerEndpointType.Userinfo) => context.Localizer[SR.ID3008], - _ => context.Localizer[SR.ID3027] + _ => context.Localizer[SR.ID3004] }); return default; diff --git a/src/OpenIddict.Validation.DataProtection/OpenIddictValidationDataProtectionHandlers.cs b/src/OpenIddict.Validation.DataProtection/OpenIddictValidationDataProtectionHandlers.cs index 352ef3ec..58d29e28 100644 --- a/src/OpenIddict.Validation.DataProtection/OpenIddictValidationDataProtectionHandlers.cs +++ b/src/OpenIddict.Validation.DataProtection/OpenIddictValidationDataProtectionHandlers.cs @@ -106,7 +106,7 @@ namespace OpenIddict.Validation.DataProtection { context.Reject( error: Errors.InvalidToken, - description: context.Localizer[SR.ID3027]); + description: context.Localizer[SR.ID3004]); return default; } diff --git a/src/OpenIddict.Validation/OpenIddictValidationHandlers.cs b/src/OpenIddict.Validation/OpenIddictValidationHandlers.cs index fadb212c..9036dbc8 100644 --- a/src/OpenIddict.Validation/OpenIddictValidationHandlers.cs +++ b/src/OpenIddict.Validation/OpenIddictValidationHandlers.cs @@ -146,7 +146,7 @@ namespace OpenIddict.Validation { context.Reject( error: Errors.InvalidToken, - description: context.Localizer[SR.ID3027]); + description: context.Localizer[SR.ID3004]); return; } @@ -253,7 +253,7 @@ namespace OpenIddict.Validation SecurityTokenSignatureKeyNotFoundException _ => context.Localizer[SR.ID3090], SecurityTokenInvalidSignatureException _ => context.Localizer[SR.ID3091], - _ => context.Localizer[SR.ID3027] + _ => context.Localizer[SR.ID3004] }); return; @@ -348,7 +348,7 @@ namespace OpenIddict.Validation context.Reject( error: Errors.InvalidToken, - description: context.Localizer[SR.ID3027]); + description: context.Localizer[SR.ID3004]); return; } @@ -590,7 +590,7 @@ namespace OpenIddict.Validation { context.Reject( error: Errors.InvalidToken, - description: context.Localizer[SR.ID3027]); + description: context.Localizer[SR.ID3004]); return default; } diff --git a/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Authentication.cs b/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Authentication.cs index 7191f654..7f655ee1 100644 --- a/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Authentication.cs +++ b/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Authentication.cs @@ -1385,7 +1385,7 @@ namespace OpenIddict.Server.IntegrationTests // Assert Assert.Equal(Errors.InvalidRequest, response.Error); - Assert.Equal(SR.FormatID3029(Parameters.CodeChallenge), response.ErrorDescription); + Assert.Equal(SR.FormatID3054(Parameters.CodeChallenge), response.ErrorDescription); Mock.Get(manager).Verify(manager => manager.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.AtLeastOnce()); Mock.Get(manager).Verify(manager => manager.HasRequirementAsync(application, diff --git a/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Discovery.cs b/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Discovery.cs index f36a2bab..b999adec 100644 --- a/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Discovery.cs +++ b/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Discovery.cs @@ -1015,7 +1015,7 @@ namespace OpenIddict.Server.IntegrationTests // Assert Assert.Equal(Errors.InvalidRequest, response.Error); - Assert.Equal("The specified HTTP method is not valid.", response.ErrorDescription); + Assert.Equal(SR.GetResourceString(SR.ID3084), response.ErrorDescription); } [Theory] diff --git a/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Exchange.cs b/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Exchange.cs index 3c4b6312..0d5821b8 100644 --- a/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Exchange.cs +++ b/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Exchange.cs @@ -637,7 +637,7 @@ namespace OpenIddict.Server.IntegrationTests // Assert Assert.Equal(Errors.InvalidRequest, response.Error); - Assert.Equal(SR.FormatID3073(Parameters.CodeVerifier), response.ErrorDescription); + Assert.Equal(SR.FormatID3073(Parameters.CodeVerifier, Parameters.CodeChallenge), response.ErrorDescription); } [Fact] @@ -1385,7 +1385,7 @@ namespace OpenIddict.Server.IntegrationTests // Assert Assert.Equal(Errors.InvalidClient, response.Error); - Assert.Equal(SR.FormatID3061(Parameters.ClientSecret), response.ErrorDescription); + Assert.Equal(SR.FormatID3053(Parameters.ClientSecret), response.ErrorDescription); Mock.Get(manager).Verify(manager => manager.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.AtLeastOnce()); Mock.Get(manager).Verify(manager => manager.HasClientTypeAsync(application, ClientTypes.Public, It.IsAny()), Times.Once()); @@ -1425,7 +1425,7 @@ namespace OpenIddict.Server.IntegrationTests // Assert Assert.Equal(Errors.InvalidClient, response.Error); - Assert.Equal(SR.FormatID3062(Parameters.ClientSecret), response.ErrorDescription); + Assert.Equal(SR.FormatID3054(Parameters.ClientSecret), response.ErrorDescription); Mock.Get(manager).Verify(manager => manager.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.AtLeastOnce()); Mock.Get(manager).Verify(manager => manager.HasClientTypeAsync(application, ClientTypes.Public, It.IsAny()), Times.Once()); @@ -1712,7 +1712,7 @@ namespace OpenIddict.Server.IntegrationTests // Assert Assert.Equal(Errors.InvalidRequest, response.Error); - Assert.Equal(SR.FormatID3029(Parameters.CodeVerifier), response.ErrorDescription); + Assert.Equal(SR.FormatID3054(Parameters.CodeVerifier), response.ErrorDescription); Mock.Get(manager).Verify(manager => manager.HasRequirementAsync(application, Requirements.Features.ProofKeyForCodeExchange, It.IsAny()), Times.Once()); diff --git a/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Introspection.cs b/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Introspection.cs index 5eb9d3a7..0e257478 100644 --- a/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Introspection.cs +++ b/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Introspection.cs @@ -561,7 +561,7 @@ namespace OpenIddict.Server.IntegrationTests // Assert Assert.Equal(Errors.InvalidClient, response.Error); - Assert.Equal(SR.FormatID3061(Parameters.ClientSecret), response.ErrorDescription); + Assert.Equal(SR.FormatID3053(Parameters.ClientSecret), response.ErrorDescription); Mock.Get(manager).Verify(manager => manager.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.AtLeastOnce()); Mock.Get(manager).Verify(manager => manager.HasClientTypeAsync(application, ClientTypes.Public, It.IsAny()), Times.Once()); @@ -599,7 +599,7 @@ namespace OpenIddict.Server.IntegrationTests // Assert Assert.Equal(Errors.InvalidClient, response.Error); - Assert.Equal(SR.FormatID3062(Parameters.ClientSecret), response.ErrorDescription); + Assert.Equal(SR.FormatID3054(Parameters.ClientSecret), response.ErrorDescription); Mock.Get(manager).Verify(manager => manager.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.AtLeastOnce()); Mock.Get(manager).Verify(manager => manager.HasClientTypeAsync(application, ClientTypes.Public, It.IsAny()), Times.Once()); diff --git a/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Revocation.cs b/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Revocation.cs index d41aeea2..02ef0258 100644 --- a/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Revocation.cs +++ b/test/OpenIddict.Server.IntegrationTests/OpenIddictServerIntegrationTests.Revocation.cs @@ -455,7 +455,7 @@ namespace OpenIddict.Server.IntegrationTests // Assert Assert.Equal(Errors.InvalidClient, response.Error); - Assert.Equal(SR.FormatID3061(Parameters.ClientSecret), response.ErrorDescription); + Assert.Equal(SR.FormatID3053(Parameters.ClientSecret), response.ErrorDescription); Mock.Get(manager).Verify(manager => manager.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.AtLeastOnce()); Mock.Get(manager).Verify(manager => manager.HasClientTypeAsync(application, ClientTypes.Public, It.IsAny()), Times.Once()); @@ -494,7 +494,7 @@ namespace OpenIddict.Server.IntegrationTests // Assert Assert.Equal(Errors.InvalidClient, response.Error); - Assert.Equal(SR.FormatID3062(Parameters.ClientSecret), response.ErrorDescription); + Assert.Equal(SR.FormatID3054(Parameters.ClientSecret), response.ErrorDescription); Mock.Get(manager).Verify(manager => manager.FindByClientIdAsync("Fabrikam", It.IsAny()), Times.AtLeastOnce()); Mock.Get(manager).Verify(manager => manager.HasClientTypeAsync(application, ClientTypes.Public, It.IsAny()), Times.Once());